Crime Instructure confirms data breach, ShinyHunters claims attack - 3.65 terabytes of stolen data to its leak site, alleging that the breach affected 275 million users across nearly 9,000 schools worldwide.

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Educational tech giant Instructure has confirmed that data was stolen in a cyberattack, with the ShinyHunters extortion gang claiming responsibility.

Instructure is a U.S.-based education technology company best known for developing Canvas, a widely used learning management system that helps schools, universities, and organizations manage coursework, assignments, and online learning.

On Friday, Instructure disclosed that it suffered a cybersecurity incident and is working with third-party cybersecurity experts and law enforcement to investigate it.

On Saturday, the company issued an update stating that the personal information of users was exposed in the breach.

"While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users," reads the updated statement.

"At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. If that changes, we will notify any impacted institutions."

As part of the response, Instructure has deployed patches, increased monitoring, and rotated application keys as a precautionary step.

Customers are required to re-authorize access to Instructure's API for new application keys to be issued.

While Instructure has not responded to BleepingComputer's questions about when the breach occurred and whether they were being extorted, the ShinyHunters extortion gang has now listed the company on its data leak site.

"Nearly 9,000 schools worldwide affected. 275 million individuals data ranging from students, teachers, and other staff containing PII," reads the data leak site.

"Several billions of private messages among students and teachers and students and other students involved, containing personal conversations and other PII. Your Salesforce instance was also breached and a lot more other data is involved."
ShinyHunters claimed that the data was stolen from Instructure via a vulnerability in their systems, which has now been patched.

This data allegedly consists of over 240 million records tied to students, teachers, and staff. The threat actor says the data contains students' names, email addresses, enrolled courses, and private messages to teachers.

Data shared by the threat actor indicates that the alleged dataset spans almost 15,000 institutions hosted across multiple geographic regions, including North America, Europe, and Asia-Pacific.

BleepingComputer has not been able to independently confirm which schools or how many individuals were impacted and has contacted Instructure with additional questions about the threat actor's claims.

Archive.
 
"At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.
This piece was the most important part of the bunch I think. At least if you want to look at it in terms of value.

Knowing precisely when someone turns of age to be a customer is really really precious.

Anyway, it's always the same. Trust the system bro, this never happens.
 
ShinyHunters blog where the data will be published
Code:
http://shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion/

1778006218793.png1778006227680.png
1778006244727.png1778006267586.png
Instructure Holdings, Inc. (Canva LMS, instructure.com)
Nearly 9,000 schools worldwide affected. 275 million individuals data ranging from students, teachers, and other staff containing PII. Several billions of private messages among students and teachers and students and other students involved, containing personal conversations and other PII. Your Salesforce instance was also breached and a lot more other data is involved. Pay or Leak.

This is a final warning to reach out by 6 May 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.

Entire list of affected schools by Instructure breach
The download button below is a list of affected schools by the Instructure Canvas LMS data breach. If any of the schools in the file are interested in preventing the release of their data please consult with a cyber advisory firm and contact us privately at TOX to negociate a settlement. You have till the end of the day by 7 May 2026 before everything is leaked and there will be no chance at a negociation for anyone.

Instructure has not even bothered speaking to us to understand the situation or to even negociate with us to prevent the release of this data. Our demand was not even as high as you might think it is. The Company seemingly does not care about all the students affected and the institutions impacted by this data breach. They still have by 6 May 2026 to come speak with us. There is no better option but to come to an agreement with us. Not paying will only worsen the situation rather than resolving it.

List of schools affected: http://91.215.85.103/pay_or_leak/instructure_affected_schools_list.txt (A)
 

Attachments

Last edited:
Fuck you assholes. Go ahead and tell the world how high my GPA was. All the rest of my identifiers got hacked years ago. Now maybe they’ll spam me with shit for smart and successful people
 
Get into tens of thousands of dollars worth of debt to have your info hacked because even the infrastructure of the degree mill is built off of is outsourced to Jeets.
 
Why does a modern chalkboard company need so much personal data? And if it does, why isn't that data stored at the schools instead of in the company database?
 
Back
Top Bottom